MAL-2026-12797

    Dashboard / Malicious Package / MAL-2026-12797

    MAL-2026-12797

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in multi-reqs (npm)

    Details: Source: amazon-inspector (38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce) The package's default export accepts (token, password) arguments and POSTs them, formatted as a Discord embed titled 'Yeni Hesap Bilgisi' with fields '🔑 Token' and '🔒 Şifre', to a hardcoded discord.com webhook URL. The destination is non-configurable, and any consumer that imports multi-reqs and invokes the default function forwards those credentials to an author-controlled Discord channel. Parameter naming and the Turkish 'Hesap Yönetim Sistemi' (Account Management System) framing indicate the module is designed to be consumed or bundled into other code as a credential-harvesting shim.

    Affected packages

    Package

    Name: multi-reqs

    Purl: pkg:npm/multi-reqs

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.2
    1.0.3
    1.0.0
    1.0.1
    MAL-2026-12797 | CVE-DB